HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-11100Published Modified CNA Chrome

CVE-2026-11100: Use after free in File Input in Google Chrome on Mac prior to 149

Use after free in File Input in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

Metrics

CVSS v3.1
9.6
Severity
CRITICAL
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability in the File Input component of Google Chrome on macOS affects all Chrome versions prior to 149.0.7827.53. The flaw is reachable over the network and requires no authentication, but does require a user to perform specific UI gestures on a crafted HTML page. Successful exploitation allows a remote attacker to escape Chrome's sandbox, gaining the ability to read, modify, or disrupt data and processes outside the browser's confined environment. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: CVE-2026-11100 is ingested from upstream advisory feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chromium or Chrome runtime.

Available
Triage

HarborGuard scores this CVE at 9.6 CRITICAL using the v3.1 vector and weights it against each environment's compliance policy to determine escalation priority; findings are routed to the appropriate team inbox within the customer org based on image ownership and policy configuration.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.53 is available on HarborGuard for any environment running an affected version. For customers with auto-remediation enabled, HarborGuard initiates a rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted HTML page over the network, so the targeted host must be reachable via a browser session to an attacker-controlled or compromised site.

  • AuthenticationNot required

    No account, credential, or session token is needed; any unauthenticated visitor to the malicious page is a valid target.

  • Victim interactionRequired

    The user must perform specific UI gestures (such as interacting with a file input element) on the crafted page, making this a social-engineering-dependent exploit.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.

Blast Radius

  • The attacker escapes Chrome's sandbox and executes arbitrary code in the context of the host macOS user process.
  • Confidential data accessible to that user (files, keychain-adjacent secrets, browser-stored credentials) becomes readable by the attacker.
  • The attacker can write or modify files and system state outside the browser sandbox, enabling persistence or lateral movement.
  • The attacker can crash or destabilize browser and OS-level processes owned by the affected user.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-11100 is active across all connected registries and pipelines the moment the advisory is ingested, covering any image that packages a Chrome or Chromium runtime below 149.0.7827.53. A rebuild targeting the fixed version is available immediately. For customers with auto-remediation enabled, HarborGuard triggers a rebuild at 149.0.7827.53, executes a regression run against the new image, and opens a pull request against affected workloads; for CRITICAL-severity issues, median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. For environments where compliance policy requires manual approval before auto-remediation, HarborGuard surfaces the finding with full CVSS context and a direct link to the patched rebuild so engineers can act without additional research overhead.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H